Silicon + architecture
Silicon shortlist (STM32, nRF, ESP32-C/S/H, EFR32, i.MX, RK35xx, TI Sitara), BOM cost and active/sleep power budgets, RTOS-vs-Linux decision, OTA architecture and security threat model before tape-out.
Services
Firmware that survives field deployment. We design and ship across the full embedded stack: bare-metal on Cortex-M0/M3, Zephyr RTOS and FreeRTOS on connected MCUs, Yocto / Buildroot Embedded Linux on Cortex-A and RISC-V application processors. MISRA C:2012 baseline, static analysis in CI, OTA with A/B rollback designed before silicon selection, BLE 5.x / Matter / Thread / LoRaWAN radio stacks, IEC 62304 for medical, ISO 26262 for automotive. Senior embedded engineers on CET with East-Coast US overlap. Fixed-scope, all-in USD delivery tiered by IoT maturity: an IoT MVP from $3,500, device management from $5,800, telemetry with a dashboard from $9,200 and a full IoT platform from $11,500. IP assigned before kickoff.
MISRA C:2012 in CI · IEC 62304-experienced · ISO 26262-experienced · IEC 61508 SIL-2 · EU CRA-ready · CET workday with 9 AM–1 PM ET overlap
Embedded products fail in the field because decisions made in the first six weeks — silicon choice, OTA architecture, security model, regulatory profile — are nearly impossible to undo at scale. We engage early. Silicon shortlist with BOM cost and active/sleep power budgets in week one. RTOS-vs-Linux decision tied to memory, real-time and field-update strategy. OTA designed before the first prototype because retrofitted OTA bricks fleets. Security threat model and SBOM produced in parallel for EU Cyber Resilience Act readiness. MISRA C:2012 enforced in CI from commit one, not bolted on the week before the IEC 62304 audit. We have shipped through Class B medical, ASIL-B automotive and SIL-2 industrial assessments — the deliverable is a product the regulator signs off on, not a slide deck.
Silicon shortlist (STM32, nRF, ESP32-C/S/H, EFR32, i.MX, RK35xx, TI Sitara), BOM cost and active/sleep power budgets, RTOS-vs-Linux decision, OTA architecture and security threat model before tape-out.
Zephyr RTOS or FreeRTOS on Cortex-M / RISC-V, MCUboot for signed updates, BLE 5.x / Thread / Matter / LoRaWAN stacks, power-managed peripherals, bare-metal where battery dictates.
Custom meta-layers built on silicon-vendor reference (meta-st, meta-imx, meta-ti, meta-rockchip), Yocto LTS (Kirkstone / Scarthgap), reproducible CI builds with sstate caching, vendor SDK for app team.
MISRA C:2012 in CI (PC-lint Plus / Cppcheck Premium / Coverity), IEC 62304 Class B/C for medical, ISO 26262 ASIL-B for automotive, IEC 61508 SIL-2 for industrial, full requirements traceability in DOORS / Polarion.
A/B partitions with RAUC / Mender / SWUpdate on Linux, MCUboot dual-slot on RTOS, signed update bundles (ed25519 / ECDSA P-256), staged rollout (canary → 1% → 10% → 100%), failure recovery designed before unit one ships.
BLE 5.x via Zephyr / SoftDevice, Matter over Thread or Wi-Fi (commissioned to CSA), LoRaWAN via Semtech LoRaMAC-node, NB-IoT / Cat-M1, Wi-SUN. FCC / CE RED / MIC pre-scan before tape-out.
The vertical decides the regulator; the device class decides the silicon, the power budget and the radio. These are the connected-hardware categories we bring up most often — each with its own constraints on memory, real-time behaviour and field-update strategy.
Coin-cell and single-charge devices where microamps decide product viability. Bare-metal or Zephyr on Cortex-M0+/M33, aggressive sleep-state management, BLE 5.x advertising and connection tuning, and a power budget measured on real silicon rather than a datasheet — typical for environmental sensors, beacons and wearables tags.
Wrist and body-worn devices pairing sensor fusion (accelerometer, PPG, temperature) with a companion mobile app. Low-power firmware, BLE data sync, on-device signal processing, and — where a clinical claim is made — IEC 62304 Class B software lifecycle with the traceability an assessor expects.
Cortex-A gateways and controllers running Yocto Embedded Linux, bridging field buses (Modbus, CAN, OPC UA) to cloud IoT. Offline-first data capture that syncs without loss, container runtimes for edge logic, and IEC 61508 SIL-2 firmware where a functional-safety case applies.
HVAC controllers, metering and lighting nodes with real-time device state and remote override over BLE, Matter-over-Thread or LoRaWAN. Mesh commissioning, scheduling, and fault-tolerant control that keeps working on a slow or dropped connection.
GNSS plus cellular (NB-IoT / Cat-M1) or LoRaWAN trackers where duty-cycling the radio is the entire battery story. Store-and-forward buffering for coverage gaps, geofencing on-device, and delta OTA that respects a metered cellular link.
Application processors (i.MX, RK35xx, TI Sitara) running perception at the edge, sharing delivery with our computer vision team. Camera pipelines, NPU/GPU acceleration, secure boot with a hardware root-of-trust, and A/B OTA on a full Linux stack.
Weeks 1–6: silicon shortlist with BOM and power budgets, RTOS-vs-Linux decision, OTA architecture, security threat model + SBOM, CRA readiness review, prototype on vendor dev board.
Yocto meta-layer or Zephyr board port, U-Boot / MCUboot bring-up, secure-boot chain (root-of-trust in OTP/eFuse), HSM / TPM integration, first signed OTA delivered to dev hardware.
Drivers, radio stack integration, application logic, MISRA C enforced in CI, unit tests on host with mocked HAL, integration tests on HIL rig, weekly demo on real hardware.
Manufacturing test fixtures, provisioning + key-injection workflow, EVT/DVT/PVT support, regulatory lab certification coordination (TÜV / Element / Eurofins), 12-month sustaining engineering retainer.
Default model. A fixed-scope IoT tier — IoT MVP, device management, telemetry with dashboard or a full platform — signed off after a free scope assessment. Silicon selection, firmware, OTA and threat model, all-in USD.
A senior pod (TPM + firmware engineer + Yocto/BSP engineer), scaling to add bootloader/security, EE liaison and HIL QA engineer. Weekly demo on real hardware. For platforms that keep evolving through production.
Post-production OTA cadence, CRA-aligned vulnerability response, Yocto LTS uplift, quarterly SBOM refresh, field-failure triage and regulatory re-cert support. Continues on the same team that built the firmware.
NDA, IP assignment and DPA aligned to GDPR signed before kickoff. Source, BSP and Yocto layers live in your repos from day one — contractual no-vendor-lock-out clause.
Most firmware shops keep the number for a sales call. Below are reference formats for different stages of IoT maturity — we name the exact quote after a free scope assessment. Embedded and IoT work is fixed-scope and all-in, quoted in USD, with no recruitment markup, no tool surcharges and no hidden fees. You see the line-item budget before any code is written and sign off on it.
IoT MVP
from $3,500
first connected device
A first working connected device. One core function, firmware on an RTOS or MCU, basic connectivity and a prototype on a vendor dev board — enough to prove the product.
Device management
from $5,800
fleet-ready
Fleet-ready firmware. Signed A/B OTA with atomic rollback, provisioning and device identity, remote configuration and secure connectivity.
Telemetry + dashboard
from $9,200
data pipeline
A telemetry pipeline and dashboard. Sensor data ingestion, a cloud backend, a monitoring dashboard, alerts and analytics on the fleet.
IoT platform
from $11,500
multi-device
A full IoT platform. Multi-device management, roles and permissions, external integrations, functional-safety evidence and CI on real hardware.
What moves the number: your regulatory profile (an unregulated consumer sensor sits well below an IEC 62304 Class C medical device or an ISO 26262 ASIL-B automotive ECU, where requirements traceability in DOORS or Polarion and independent-assessor evidence add real engineering workload); RTOS-vs-Embedded-Linux scope (a single bare-metal control loop on a Cortex-M0+ vs a Yocto BSP with a custom meta-layer, secure boot and A/B OTA on a Cortex-A application processor); radio and connectivity certification (a wired device vs BLE 5.x, Matter-over-Thread or LoRaWAN needing FCC Part 15, CE RED and full lab certification); and silicon maturity (a well-supported vendor dev board vs a bring-up on new silicon with an immature BSP). Regulatory lab-certification fees (TÜV / Element / Eurofins) run on your own accounts, so you keep the cost lever. Prices are indicative and are fixed in a written quote for your specific scope.
Android + iOS refactor and rebuild for a German last-mile logistics operator — multi-point route planning, real-time driver tracking and in-app invoicing live in the EU.
Property marketplace web platform with listing CMS, search and B2B admin console for US and EU operators.
Native iOS and Android e-signature clients with a Symfony + React CRM for a cross-border law firm — KYC onboarding and a defensible evidence trail for US & EU matters.
Embedded work lives or dies on the regulator, the radio and the field-failure path. We pair senior firmware engineering with domain-specific conformance across US & EU markets, and share delivery with our cloud & DevOps team for IoT backends and OTA infrastructure, our mobile app team for companion apps, and our computer vision team when perception runs on the edge.
IEC 62304 Class B/C device software with full requirements traceability in DOORS or Polarion, prepared for the assessor rather than invented the week before the audit — we have shipped Class B and supported Class C.
HealthTech →IEC 61508 SIL-2 firmware and offline-first control — an MES that captures every step reliably in a reactor environment and syncs to the central server without data loss, the kind of audit-ready industrial build behind our CheckList work.
Manufacturing →ISO 26262 ASIL-B firmware under a functional safety manager, contributing to ASIL-D safety cases, with secure OTA, image signing and anti-rollback for connected-vehicle and micromobility fleets that update in the field.
Mobility →Connected HVAC, metering and smart-building controllers with real-time device state, scheduling and remote override over BLE / Matter / LoRaWAN — the kind of instant, fault-tolerant control behind our ClimateHome smart-HVAC build.
Energy →GDPR-aligned · ISO 27001 ready · SOC 2 Type II in progress · IEC 62304-experienced · ISO 26262-experienced · CRA-ready
Every embedded engineer has shipped product through EVT/DVT/PVT and lived through field failures. Silicon, RTOS, OTA and security decisions are made by people who have paid the cost of getting them wrong.
EU Cyber Resilience Act readiness from day one: SBOM, vulnerability disclosure policy, security update commitment, threat model. EU customer data and telemetry land in eu-central-1 / eu-west-1 with Schrems II-aligned DPA.
MISRA C:2012 in CI from commit one. IEC 62304, ISO 26262, IEC 61508 evidence prepared for the assessor, not invented the week before the audit. We have shipped through Class B medical, ASIL-B automotive, SIL-2 industrial.
For regulated devices we work alongside your QA / regulatory team with full traceability from requirements (DOORS or Polarion) through design, code, unit and integration tests — the assessor sees a paper trail, not a paper trail invented in retrospect.
Smart-home HVAC control needs to be instant and fault-tolerant. YuSMP built the mobile app with real-time device state updates, scheduling, and remote override that works even on a slow cellular connection. User satisfaction scores jumped 25% post-launch.
Process control in a reactor environment cannot afford connectivity gaps. YuSMP delivered an offline-first MES that captures every step reliably and syncs to the central server without data loss. Audit readiness that once took days now takes minutes.
Decision is driven by hardware budget, real-time requirements, regulatory profile and field-update strategy. Bare-metal (no scheduler) when you have a single tight control loop on a Cortex-M0/M0+, sub-kilobyte RAM, and battery life is the dominant concern — typical for sensors and BLE peripherals. Zephyr RTOS when you need a real-time scheduler, networking stack (TCP/IP, BLE, Thread, Matter), multiple concurrent tasks, but RAM budget is 32–512 KB and you want a Linux Foundation-governed project with long-term support. FreeRTOS for legacy stacks and where Amazon FreeRTOS / AWS IoT integration is required. Embedded Linux via Yocto (or Buildroot for smaller systems) when you have an application processor (Cortex-A / RISC-V), ≥64 MB RAM, need a full network stack, container runtime, or third-party libraries that assume POSIX.
Both, with strong preference for the latter as a starting point. We start from the silicon vendor's reference Yocto layer (meta-st-stm32mp, meta-ti, meta-imx, meta-nxp, meta-raspberrypi, meta-rockchip, etc.) and build a custom meta-layer for your product. Recipes are version-pinned to a Yocto LTS release (Kirkstone / Scarthgap), bitbake builds run reproducibly in CI (GitLab or GitHub Actions with sstate caching on S3 — without sstate caching a clean Yocto build is 90 minutes of pure CI cost). We deliver a SDK so your application team can cross-compile without touching the BSP, and we maintain the layer as part of the engagement.
MISRA C:2012 (with Amendment 3 directives) is our default static-analysis baseline on every embedded engagement — enforced via PC-lint Plus, Cppcheck Premium, or Coverity in CI with deviations documented and reviewed. For medical devices we deliver against IEC 62304 (software lifecycle for medical device software) with full traceability from requirements through design, code and unit/integration tests in DOORS or Polarion; we have shipped Class B and supported Class C audits. For automotive we work to ISO 26262 ASIL-B and contribute to ASIL-D safety cases under a functional safety manager. For industrial we handle IEC 61508 SIL-2. We do not self-certify — independent assessor sign-off is your audit body, we prepare the evidence.
OTA is designed before silicon is chosen — late-stage OTA retrofits are how fleets get bricked. Embedded Linux uses A/B partitioning (RAUC, Mender, or SWUpdate) with atomic rollback on boot failure, signed update bundles (typically ed25519 or ECDSA P-256), and a delta-update mechanism for cellular-constrained devices. RTOS devices use MCUboot for secondary-slot updates with image signing and anti-rollback counters. Backend is your own or hyperscale IoT (AWS IoT Device Management, Azure Device Update for IoT Hub, Mender server). We design the staged rollout policy (canary → 1% → 10% → 100%) and the field-failure recovery path before first production unit ships.
BLE 5.x via Zephyr's stack on Nordic nRF52/nRF53/nRF54 and Silicon Labs EFR32, or SoftDevice when vendor-specific certifications require it. Matter (formerly Project CHIP) via the official open-source Matter SDK on Thread (OpenThread) or Wi-Fi transport — we have shipped commissioned Matter-over-Thread devices through CSA certification. LoRaWAN via the Semtech LoRaMAC-node stack on STM32WL or SX126x companion chips, with TTN / ChirpStack backends. Sub-GHz proprietary protocols (Wi-SUN, Z-Wave) where the use case justifies the BOM cost. We do regulatory pre-scan (FCC Part 15, CE RED, MIC) before tape-out and coordinate full lab certification with a partner (TÜV, Element, Eurofins).
Embedded and IoT work is fixed-scope and tiered by IoT maturity, all-in and quoted in USD. An IoT MVP runs from $3,500 (first working connected device: one core function, firmware, basic connectivity); device management from $5,800 (signed A/B OTA with rollback, provisioning, remote config); telemetry with a dashboard from $9,200 (sensor ingestion, cloud backend, monitoring dashboard, alerts); a full IoT platform from $11,500 (multi-device management, roles, integrations, safety evidence, CI on real hardware). The exact number depends on your regulatory profile (IEC 62304, ISO 26262, IEC 61508), RTOS-vs-Embedded-Linux scope, radio and connectivity certification (FCC Part 15, CE RED for BLE / Matter / LoRaWAN) and silicon maturity. You see the line-item budget after a free scope assessment and sign off before any code is written. Source, BSP and Yocto layers live in your repos from day one; production hand-off includes manufacturing test fixtures, the Yocto SDK and a CI release pipeline — no recruitment markup, no tool surcharges, and regulatory lab-certification fees run on your own accounts.
Yes — brownfield takeover is a large share of our embedded work. We start with a firmware audit: build reproducibility (can we rebuild your exact shipping binary from source?), toolchain and SDK version pinning, a MISRA C:2012 static-analysis baseline to quantify existing debt, and a review of the OTA, secure-boot and secrets-handling design. You get a written findings report with a risk-ranked remediation plan before we touch a line of code. Common triggers are an original vendor or contractor who has gone dark, a Yocto BSP frozen on an end-of-life kernel, or a device that needs EU Cyber Resilience Act compliance it was never designed for. We can also do the audit as a standalone engagement without committing to the rebuild.
We are a firmware and embedded-software house, not a PCB design bureau — but we do not work in isolation from the hardware. We drive silicon selection (MCU/SoC shortlist with BOM cost and active/sleep power budgets), review your schematic and pin-mux from a firmware-feasibility angle, and write bring-up and manufacturing-test firmware for the board. For the physical PCB layout, RF matching and EMC design we work alongside your EE team or one of our hardware partners, and we own the software boundary end to end: BSP, bootloader, drivers, application firmware and OTA. If you arrive with a dev board and a datasheet, that is a normal starting point.
Power is a design constraint from week one, not a late-stage tuning pass. We build an energy budget on real silicon — measured active, idle and deep-sleep currents with a power analyzer (Otii, Nordic PPK2 or lab equipment), not datasheet typicals. Firmware is architected around the lowest viable sleep state: peripheral clock gating, DMA instead of CPU polling, event-driven wake rather than busy loops, and radio duty-cycling (BLE connection-interval and advertising tuning, or store-and-forward on cellular). We give you a projected battery-life figure tied to a defined usage profile and validate it against a real coin cell or pack, because a device that meets its power spec on paper and fails in the field is a recall waiting to happen.
Security is designed in, with the EU Cyber Resilience Act as the baseline for connected devices sold into the EU. We implement a secure-boot chain with the root-of-trust in OTP/eFuse, signed firmware images (ed25519 or ECDSA P-256) with anti-rollback counters, and encrypted-at-rest secrets via the SoC secure element, HSM or TPM. OTA bundles are signed and verified before they are applied. On the process side you get an SBOM, a documented threat model, a vulnerability-disclosure policy and a security-update commitment — the artefacts a CRA conformity assessment asks for. Key provisioning and injection happen in a controlled manufacturing workflow so private keys never live in the source tree. For medical and automotive work this dovetails with the IEC 62304 / ISO 26262 evidence trail rather than sitting beside it.
Practical guides on embedded development, custom software costs, and build-vs-buy decisions.
Share a few details and a senior consultant will reply within one business day.